Skip to content

ibondarenko1/blue-team-engagement

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Enterprise Network Defense - A One-Week Blue Team Stress Test

A controlled, one-week red-team / blue-team engagement on an isolated enterprise lab network. Scenario client: SecureNet Inc. A live opposing red team. A full hardening-and-defense lifecycle, documented end to end.

The lab was controlled and the client is a scenario. The defensive work, the SIEM stack, the incident response, and the forensics are real.

Deployed network topology

At a glance

Duration One week, end to end
Role Incoming security consultant, blue team
Estate 8 in-scope systems - a Windows domain, web and application servers, a SIEM, the perimeter firewall
Opposition A live red team, attacking from kickoff with no preparation window
Result 1 host compromised, 1 contained attempt, 6 systems with no exploitation

Outcome

Across a week of sustained attack, one host was genuinely compromised (a web-RCE reverse shell), detected and contained in roughly 55 minutes. One host saw web shells uploaded but never executed - a contained attempt. Six systems showed no exploitation, confirmed by an end-of-window forensic sweep. The one compromise is documented in full, and so is a forensic correction made when fuller analysis contradicted the first read. See Outcome and Forensics.

Contents

This repository is the engagement report. Read it in order, or jump to any section. Each page links to the next at its foot.

Report

  1. Executive Summary
  2. The Environment
  3. Initial State: Day One
  4. Engagement Timeline - the day-by-day walkthrough of the whole week
  5. Hardening: Firewall
  6. Hardening: Credentials and Active Directory
  7. Hardening: Per-Host
  8. Detection and Deception
  9. Monitoring and Response Stack

Incident reports

  1. SO-1: Shellshock Exploitation Attempt
  2. SO-2: Web RCE Compromise
  3. SO-3: OwnCloud GraphAPI Probe
  4. SO-4: HTTP Request Smuggling
  5. SO-5: Multi-Port Scan and RDP DoS

Closing and appendices

  1. Outcome and Forensics
  2. Recommendations
  3. Appendix A: Change Log
  4. Appendix B: Tools and Techniques
  5. Appendix C: MITRE ATT&CK Coverage

Supporting material

Path Contents
detection/ The custom Sigma detection rule pack deployed in Security Onion
automation/ The response-automation daemons - alert bridge, auto-block, auto-unblock, watchdog, uptime monitor - as clean reference implementations
methodology/ The change-management and structured-remediation methods used during the engagement
assets/ The topology diagram and the script that generates it; embedded screenshots

Skills demonstrated

  • SIEM operations - Security Onion (Suricata, Zeek, Sigma, Elasticsearch and the Kibana Hunt interface)
  • Detection engineering - a custom Sigma rule pack, MITRE ATT&CK mapped
  • Network security - pfSense firewall hardening, segmentation, and alias-based blocking with a time-bounded auto-block pipeline
  • Windows and Active Directory hardening - CIS benchmarks, krbtgt rotation, privilege-sprawl cleanup, AS-REP roasting mitigation
  • Linux hardening - SSH, Samba, UFW, auditd, fail2ban
  • Incident response and host forensics under live time pressure
  • Disciplined change management - an append-only registry where every change carries a rollback and a re-apply command

Controlled lab exercise. SecureNet Inc. is a fictional scenario company. The lab uses private RFC1918 addressing throughout.

About

One-week red-team / blue-team enterprise network defense engagement: case study, custom Sigma detection pack, and methodology.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors